silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file.
Link | Tags |
---|---|
http://secunia.com/advisories/16659/ | third party advisory |
http://www.zataz.net/adviso/silc-server-toolkit-06152005.txt | |
http://www.securityfocus.com/bid/14716 | vdb entry |
http://www.securityfocus.com/archive/1/409672 | mailing list |
http://bugs.gentoo.org/show_bug.cgi?id=94587 | patch |